CVE-2019-11870: XSS
Published May 9, 2019
·Updated
Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/mediachoose.tpl Editor Preview feature or the templates/2k11/admin/mediaitems.tpl Media Library feature.
Affected Software
1 affected component
S9Y serendipity<2.1.5
Event History
May 9, 2019
CVE Published
via MITRE·09:25 PM
Data Sourced
via MITRE·09:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-11870?
CVE-2019-11870 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2019-11870?
To fix CVE-2019-11870, upgrade Serendipity to version 2.1.5 or later, which addresses the XSS vulnerability.
3
What types of attacks are possible with CVE-2019-11870?
CVE-2019-11870 can be exploited to perform cross-site scripting attacks through manipulated EXIF data.
4
Which versions of Serendipity are affected by CVE-2019-11870?
CVE-2019-11870 affects all versions of Serendipity before 2.1.5.
5
What features are vulnerable in CVE-2019-11870?
The vulnerability in CVE-2019-11870 affects the Editor Preview feature and Media Library feature in Serendipity.